diff --git a/.env.example b/.env.example index 4d21c9b..e5aa7fa 100644 --- a/.env.example +++ b/.env.example @@ -13,10 +13,11 @@ EMIT_SECRET= SMTP_USERNAME= SMTP_PASSWORD= -# Email OTP on sign-in. Leave true; only the exact value "false" makes sign-in -# password only (logged as OTP_BYPASSED, shown on the login page and top bar). +# Email OTP on sign-in. Off by default; only the exact value "true" turns it on, +# and that needs working SMTP. While off, sign-in is password only (logged as +# OTP_BYPASSED, shown on the login page and top bar). # Applied to app/config.php by the php container on every start. -OTP_REQUIRED=true +OTP_REQUIRED=false # Port to expose the web app on (default 80) HTTP_PORT=80 diff --git a/app/assets/utils/otp_policy.php b/app/assets/utils/otp_policy.php index 69303b2..b90abc8 100644 --- a/app/assets/utils/otp_policy.php +++ b/app/assets/utils/otp_policy.php @@ -3,21 +3,22 @@ // // Email OTP login policy, set by OTP_REQUIRED in config.php. // -// Fails safe: the OTP step is off only when the constant is defined and is -// exactly the boolean false. A missing constant (any config.php written before -// this switch existed), 0, 'false' or a typo all keep it on. +// OFF BY DEFAULT: the OTP step runs only when the constant is defined and is +// exactly the boolean true. A missing constant (any config.php written before +// this switch existed), 1, 'true' or a typo all leave it off, so sign-in is +// password only and no SMTP is needed to log in. // // While it is off, every sign-in that skips the OTP because of it is logged as // OTP_BYPASSED, and the login page and top bar both say so on screen — a -// weakened sign-in must never be invisible to whoever is using it. +// password-only sign-in must never be invisible to whoever is using it. // -// Only the login OTP is affected. The staff/viewer and no-SMTP skips in -// login_otp.php still apply when it is on, and password-reset OTPs -// (PasswordResetManager) are a separate flow that stays on regardless. +// Only the login OTP is affected. When it is on, the staff/viewer and no-SMTP +// skips in login_otp.php still apply; password-reset OTPs (PasswordResetManager) +// are a separate flow that stays on regardless. if (!function_exists('otp_required')) { function otp_required(): bool { - return !(defined('OTP_REQUIRED') && OTP_REQUIRED === false); + return defined('OTP_REQUIRED') && OTP_REQUIRED === true; } } @@ -26,7 +27,7 @@ if (!function_exists('otp_log_bypass')) { // log (the container's Apache log) under a fixed, greppable tag. function otp_log_bypass($user_id, string $where): void { error_log(sprintf( - '[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED=false in config.php', + '[auth] OTP_BYPASSED user_id=%d ip=%s where=%s -- OTP_REQUIRED is not true in config.php', (int)$user_id, $_SERVER['REMOTE_ADDR'] ?? '-', $where diff --git a/app/config.example.php b/app/config.example.php index 5d9d720..0366161 100644 --- a/app/config.example.php +++ b/app/config.example.php @@ -39,13 +39,12 @@ if (!defined('NODE_EMIT_SECRET')) { } // ── Login OTP ──────────────────────────────────────────────────────────────── -// Email OTP on sign-in. LEAVE THIS TRUE unless password-only sign-in is wanted -// on purpose (e.g. a demo). It fails safe: anything other than the boolean -// false — the constant being absent included — keeps the OTP step on. While it -// is off, every sign-in is logged as OTP_BYPASSED and the login page and top -// bar both say so. Password-reset OTPs are not affected. +// Email OTP on sign-in. OFF BY DEFAULT: only the boolean true turns it on — +// anything else, the constant being absent included, leaves sign-in password +// only (logged as OTP_BYPASSED, shown on the login page and top bar). Turn it +// on only with working SMTP. Password-reset OTPs are not affected. if (!defined('OTP_REQUIRED')) { - define('OTP_REQUIRED', true); + define('OTP_REQUIRED', false); } // ── Usage packages ─────────────────────────────────────────────────────────── diff --git a/app/include_topbar.php b/app/include_topbar.php index 3f77d7f..9999cd6 100644 --- a/app/include_topbar.php +++ b/app/include_topbar.php @@ -199,12 +199,12 @@ $_usage_full = $_usage_max_pct >= 100; - +